Information disclosure in ePMP - CVE-2017-7918

 

Information disclosure in ePMP - CVE-2017-7918

Published: June 20, 2017 / Updated: September 14, 2018


Vulnerability identifier: #VU7133
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7918
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to insufficient access control. A remote attacker can use specific MIBs, trigger device configuration backups after a valid user has used SNMP configuration export, gain access to sensitive information and possibly change configuration.

Successful exploitation of the vulnerability results in information disclosure.


Affected software

ePMP

How to mitigate CVE-2017-7918

Update to version 3.4-RC7 or later.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins